GregLab | Exam Prep

Identify the core features and objects of Microsoft 365 services

Zero Trust and Defender XDR

Apply foundational Zero Trust reasoning and recognize how Defender XDR unifies cross-workload detection and response.

What you need to know

  • Zero Trust uses three principles: verify explicitly, use least privilege, and assume breach.
  • Authentication establishes identity; authorization decides what an authenticated principal may do.
  • Threat intelligence provides context about adversaries and indicators; threat protection uses signals and controls to prevent, detect, investigate, and respond.
  • Defender XDR correlates alerts across supported identity, endpoint, email, app, and cloud workloads into incidents.

Objects and administrative surfaces

  • Incidents, alerts, advanced hunting, and automated investigation — Microsoft Defender portal.
  • Identity and access policy — Microsoft Entra admin center.

How it works

  • Defender XDR correlation helps analysts see a connected attack story instead of investigating isolated alerts.
  • Assume breach means limit blast radius and continuously monitor; it does not mean abandon prevention.

When to use it

  • Use Defender XDR to investigate a correlated incident and threat intelligence to enrich what an indicator or actor means.
  • Use Conditional Access or resource permissions for access enforcement, not Defender incident records.

Security and governance implications

  • Grant analysts only the roles needed for investigation and response.
  • Pair prevention and access controls with monitoring and response evidence.

Troubleshooting signals

  • Start from the incident timeline, affected entities, and correlated alerts.
  • Confirm the relevant Defender workload is onboarded and producing signals.

Exam traps

  • MFA is an authentication control, not an authorization rule.
  • Defender XDR is not the place to assign Microsoft 365 product licenses or SharePoint permissions.

Key takeaways

  • Verify explicitly; use least privilege; assume breach.
  • Defender XDR joins related signals into incidents for coordinated investigation.

Related objectives

  • D1.2.a
  • D1.2.b
  • D1.2.c
  • D1.2.d
  • D1.2.e

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, clearly labeled supplemental exercises, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources